Services / Compromise Assessment
Confirm it, scope it, contain it.
Something looks wrong and nobody can say whether it's serious. This is the engagement that turns that suspicion into a yes or a no, with a containment order attached either way.
The difference
The dangerous answer is "probably fine".
Most teams in this position get told to keep monitoring. That's not an answer — it's the same uncertainty with more hours attached, while an attacker who is present keeps working and an attacker who isn't costs you a fortune in caution.
We time-box it. Identity logs, endpoints, cloud control planes and egress, hunted for the specific behaviours that indicate a live intrusion — and then we say yes, no, or exactly what we'd need to be sure.
How it works
From suspicion to a decision.
-
01
Take the trigger seriously
The alert, the odd login, the ransom note, the tip from a third party. We start from what made you call, not from a generic sweep.
-
02
Hunt where intrusions live
Identity and authentication first, then endpoints, cloud control planes and outbound traffic — the places persistence actually hides.
-
03
Scope the blast radius
If something is there, what did it touch: which accounts, which data, which systems, and for how long.
-
04
Hand over a containment order
Sequenced actions — what to isolate, what to reset, in what order — written so it can be executed under pressure.
What you get
A straight answer, fast.
-
A verdict
Compromised, not compromised, or precisely what evidence is missing. No hedging.
-
Blast-radius scope
Accounts, endpoints, data and dwell time, so legal and comms know what they're dealing with.
-
Containment order
Sequenced, prioritised actions — not a list of everything that could theoretically be done.
-
Notification-ready facts
The findings your regulator, insurer or counsel will ask for, documented as they were found.
Something feels wrong?
Tell us what you're seeing. We'll tell you plainly whether it's worth an engagement — including when it isn't.